This Data Processing Addendum ("DPA") forms part of the Terms between WebsiteDev. Solutions GmbH ("Processor") and the Customer ("Controller") and applies where we process personal data contained in Customer Data on the Controller's behalf. Where terms like "personal data", "processing", "controller" and "processor" are defined in applicable data-protection law (including the UK/EU GDPR), those meanings apply.
Roles and instructions
The Controller determines the purposes and means of processing Customer Data; the Processor processes it only on the Controller's documented instructions (including as set out in the Terms and by use of the service), unless required by law.
Subject matter and duration
Subject matter: provision of the service. Duration: the term of the Terms. Nature and purpose: hosting, storing, transmitting and displaying Customer Data, telephony, reporting and on-server AI summaries. Data subjects: the Controller's leads, clients and contacts. Data types: as entered by the Controller — typically name, contact details, call records/notes and related sales information.
Processor obligations
- Confidentiality: ensure people authorised to process the data are bound by confidentiality.
- Security: implement appropriate technical and organisational measures (encryption in transit, tenant isolation, access controls, audit logging).
- Sub-processors: the Controller authorises the sub-processors we use to run the service (hosting/infrastructure and, where the Controller uses those features, telephony, number-lookup and email providers). We remain responsible for them and will impose equivalent obligations. We will inform the Controller of intended changes and allow reasonable objection.
- Assistance: help the Controller respond to data-subject requests and meet its security, breach-notification and impact-assessment obligations, taking into account the nature of processing.
- Breach: notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data.
- Deletion/return: on termination, delete or return Customer Data (Controller's choice) after a reasonable period, save where law requires retention.
- Audit: make available information needed to demonstrate compliance and allow reasonable audits, subject to confidentiality and security.
International transfers
Where processing involves cross-border transfers, the parties will rely on an approved transfer mechanism (such as standard contractual clauses), which are incorporated by reference where required.
Contact
Data protection contact: privacy@tradecrm.digital.